Research
Security News
Threat Actor Exposes Playbook for Exploiting npm to Build Blockchain-Powered Botnets
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
pull-update
Advanced tools
A small, but powerful Javascript library crafted to power your webapp's pull to refresh feature. No markup needed, highly customizable and dependency-free!
If you found this project useful, please consider making a donation.
Download PulltoRefresh either from the NPM Registry, CDNJS or UNPKG:
$ npm install pulltorefreshjs --save-dev
$ wget -O pulltorefresh.js https://unpkg.com/pulltorefreshjs
Include the JS file in your webapp and initialize it:
const ptr = PullToRefresh.init({
mainElement: 'body',
onRefresh() {
window.location.reload();
}
});
Bundlers can consume pulltorefreshjs
as CommonJS and ES6-modules syntax:
import PullToRefresh from 'pulltorefreshjs';
// or
const PullToRefresh = require('pulltorefreshjs');
init(options)
Will return a unique ptr-instance with a destroy()
method.destroyAll()
Stop and remove all registered ptr-instances.setPassiveMode(isPassive)
Enable or disable passive mode for event handlers (new instances only).distThreshold
(integer)
Minimum distance required to trigger the refresh.
60
distMax
(integer)
Maximum distance possible for the element.
80
distReload
(integer)
After the distThreshold
is reached and released, the element will have this height.
50
distIgnore
(integer)
After which distance should we start pulling?
0
mainElement
(string)
Before which element the pull to refresh elements will be?
body
triggerElement
(string)
Which element should trigger the pull to refresh?
body
ptrElement
(string)
Which class will the main element have?
.ptr
classPrefix
(string)
Which class prefix for the elements?
ptr--
cssProp
(string)
Which property will be used to calculate the element's proportions?
min-height
iconArrow
(string)
The icon for both instructionsPullToRefresh
and instructionsReleaseToRefresh
⇣
iconRefreshing
(string)
The icon when the refresh is in progress.
…
instructionsPullToRefresh
(string)
The initial instructions string.
Pull down to refresh
instructionsReleaseToRefresh
(string)
The instructions string when the distThreshold
has been reached.
Release to refresh
instructionsRefreshing
(string)
The refreshing text.
Refreshing
refreshTimeout
(integer)
The delay, in milliseconds before the onRefresh
is triggered.
500
getMarkup
(function)
It returns the default HTML for the widget, __PREFIX__
is replaced.
getStyles
(function)
It returns the default CSS for the widget, __PREFIX__
is replaced.
onInit
(function)
The initialize function.onRefresh
(function)
What will the pull to refresh trigger? You can return a promise.
window.location.reload()
resistanceFunction
(function)
The resistance function, accepts one parameter, must return a number, capping at 1.
t => Math.min(1, t / 2.5)
shouldPullToRefresh
(function)
Which condition should be met for pullToRefresh to trigger?
!window.scrollY
• Please note that this default is useful whenever you're setting mainElement as the body of the document, if you need it in another element with overflow, use !this.mainElement.scrollTop
. Refer to the multiple instances demo for reference.With ReactDOMServer and renderToString()
you can use components as
icons instead of just strings.
In this example we also use Font Awesome to get nice icons with animation, but you can
use any React component you like.
import React, { Component } from 'react';
import ReactDOMServer from 'react-dom/server';
import PullToRefresh from 'pulltorefreshjs';
import { faSyncAlt} from '@fortawesome/free-solid-svg-icons';
import { FontAwesomeIcon } from '@fortawesome/react-fontawesome';
class App extends Component
{
componentDidMount()
{
PullToRefresh.init({
mainElement: 'body',
onRefresh() {
window.location.reload();
},
iconArrow: ReactDOMServer.renderToString(
<FontAwesomeIcon icon={faSyncAlt} />
),
iconRefreshing: ReactDOMServer.renderToString(
<FontAwesomeIcon icon={faSyncAlt} spin={true} />
),
});
}
componentWillUnmount()
{
// Don't forget to destroy all instances on unmout
// or you will get some glitches.
PullToRefresh.destroyAll();
}
render()
{
return (
<div>
<h1>App</h1>
</div>
);
}
}
export default App;
To quickly start the development workflow:
nvm use 10 && npm install
npm run dev
This will watch and compile the bundle for browser usage.
E2E tests are executed with Testcafé.
npm test
to fire tests in the default browser, use BROWSER
to change thismake
to setup the dependencies and run tests only (e.g. CI)Advanced debug can be achieved with testcafe-live
, e.g.
$ npm test --live chrome tests/e2e/cases --debug-on-fail
onPullStart
, onPullDown(direction, willRefresh)
, onRelease(willRefresh)
FAQs
Pull To Refresh
The npm package pull-update receives a total of 1 weekly downloads. As such, pull-update popularity was classified as not popular.
We found that pull-update demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A threat actor's playbook for exploiting the npm ecosystem was exposed on the dark web, detailing how to build a blockchain-powered botnet.
Security News
NVD’s backlog surpasses 20,000 CVEs as analysis slows and NIST announces new system updates to address ongoing delays.
Security News
Research
A malicious npm package disguised as a WhatsApp client is exploiting authentication flows with a remote kill switch to exfiltrate data and destroy files.